Vulnerabilities > Xylem

DATE CVE VULNERABILITY TITLE RISK
2022-03-18 CVE-2020-25176 Path Traversal vulnerability in multiple products
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system.
network
low complexity
schneider-electric rockwellautomation xylem CWE-22
critical
9.8
2022-03-18 CVE-2020-25178 Cleartext Transmission of Sensitive Information vulnerability in multiple products
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP.
8.8
2022-03-18 CVE-2020-25180 Use of Hard-coded Credentials vulnerability in multiple products
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands.
6.5
2022-03-18 CVE-2020-25182 Uncontrolled Search Path Element vulnerability in multiple products
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries.
6.7
2022-03-18 CVE-2020-25184 Insufficiently Protected Credentials vulnerability in multiple products
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file.
5.5
2022-02-07 CVE-2021-42833 Use of Hard-coded Credentials vulnerability in Xylem Aquaview 1.60
A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.
local
low complexity
xylem CWE-798
8.8
2021-12-08 CVE-2021-41063 SQL Injection vulnerability in Xylem Aanderaa Geoview
SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attackers to execute arbitrary commands.
network
low complexity
xylem CWE-89
critical
9.8